Back to skill

Security audit

三剪客 · 动作迁移

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about using a third-party paid media API, but it ships a broader generic marketplace client than the action-transfer purpose implies.

Review before installing. Use this only if you are comfortable sending public image/video URLs and an A7W API key to a third-party paid service. Prefer a limited/revocable API key, do not use --host or A7W_HOST unless you fully trust the destination, and constrain any agent use to action_transfer submit/query rather than the generic app/API commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a narrowly scoped action-transfer wrapper, but the documented client supports broader functions: enumerating apps, retrieving arbitrary schemas, dumping all plugin schemas locally, storing credentials, checking usage, and calling any app/API. This mismatch can mislead users and hosting agents into granting trust or permissions for a single-purpose media workflow while actually exposing a general-purpose API client that can access other services and write local artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is explicitly a generic client for calling any plugin in the a7w marketplace, while the skill is घोषित as action-transfer only. This violates least privilege and allows an agent using this skill to access unrelated capabilities, expanding the attack surface and enabling unintended API actions with the user's API key.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The call command accepts arbitrary app and api names and arbitrary JSON bodies, giving the skill a general-purpose API invocation primitive. In the context of an action-transfer skill, this is dangerous because prompt-influenced or tool-driven use could invoke unrelated marketplace functionality, causing unauthorized actions, data exposure, or unexpected charges on the user's account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill documentation is presented only in Chinese, including setup, safety notes, and contact instructions, with no indication that users may use another language or request a localized version. This creates a language policy concern because it effectively imposes a specific language on users without opt-in or alternatives.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 13)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 124)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

30 秒上手

bash
# 1. 配一次 Key(去 https://api.a7w.cn/ 注册即可领取)
python3 scripts/client.py login --key sk-你的key

# 2. 提交任务:一张人物图 + 一段视频,两个都要公网可访问的地址

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes a general-purpose client that can enumerate apps, inspect schemas, call arbitrary APIs, and query account/task metadata beyond the advertised action-transfer function. This expands the operational scope of the skill and can mislead users or host agents into granting broader API access than necessary, increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requests or implies capabilities including environment access, file read/write, shell, and network, but does not declare explicit tool scope in machine-readable permissions. That weakens least-privilege enforcement and makes it harder for a host or reviewer to constrain execution to the documented behavior. In this context, the skill also references a local client script and credential storage, so undeclared capability breadth materially increases review and containment risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name, description, summary, and main body begin in Chinese and the document does not provide an alternate language option or indicate that Chinese is optional. This can violate a language/locale policy when users are not given a choice of language.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-query.md (reported line 38)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/action_transfer/query" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes uploading reference images and input videos to a remote third-party API but does not warn users that potentially sensitive biometric and video data will be transmitted off-platform. This creates a privacy and consent risk because users may unknowingly send personal media to an external service, especially given the face-processing context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The cURL example confirms that the skill sends user-provided image and video URLs plus an API key to an external endpoint, which is an external data transmission path. In this skill context, that is expected functionality, but it is still security-relevant because it involves third-party transfer of potentially sensitive media and credentials if users do not understand the trust boundary.

Content

Scanner excerpt · references/api-submit.md (reported line 79)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/action_transfer/submit" \

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module documentation openly states that the tool lets a skill call any plugin in the marketplace, contradicting the declared action-transfer-only scope. In skill ecosystems, this kind of scope mismatch is security-relevant because it signals hidden or excess capability that an agent may later exercise outside user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The dump logic enumerates all available plugins and exports their schemas, which is unnecessary for a skill that should only generate and query action-transfer tasks. This capability can be used to map the broader platform, discover sensitive or high-impact APIs, and facilitate later misuse of the user's credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The stated purpose is generating action-transfer videos, but the README advertises broader platform offerings such as an AI plugin market, video super-resolution, batch video remixing, and an AI Agent platform. This expands the apparent scope from a single-purpose skill to a gateway for unrelated services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill documentation is presented only in Chinese, with no indication that other languages are supported or that the locale is intentionally constrained. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.